Release date 2026/08/10
Bugfix
-
Security: Fixed CVE-2026-14917 in the SAML plugin by always validating the
samlp:Responsesignature whenidp_certificateis configured correctly, and logging a warning if misconfigured. This prevents a crafted unsigned SAML response from silently bypassing authentication whenvalidate_assertion_signatureis set to false.